Four Defender protections that are off by default on Windows Home (and how to turn them on without gpedit)
Microsoft Defender on Windows 10/11 Home ships with four protections that exist but are not enforced by default. What each one does, what the default is, how to enable it with PowerShell, and what can go wrong afterwards — using only Microsoft's own documentation and measurements on my PC.
Product: Agent Fettle
When I cancelled Norton and went back to Microsoft Defender, I wanted to know whether Defender's defaults were actually good enough — measured, not assumed.
The short version: Defender on Windows 10/11 Home has four protections that exist but are not enforced by default, and because Home has no Group Policy editor (gpedit.msc), the only way to turn them on is PowerShell or the registry.
This article covers those four, in the order "what it does", "what the default is", "how to enable it", and "what can go wrong once it is on", using nothing but Microsoft's primary documentation and measurements on my own PC.
Scope
- Windows 10 22H2 / Windows 11, an ordinary PC that is not onboarded to Defender for Endpoint (the enterprise product)
- The commands that only read state work in a non-elevated PowerShell. Only the commands that change something need an administrator PowerShell
- The Defender engine itself is an AV-TEST Top Product (June 2026, same rating as Norton 360)1. The problem is not the engine — it is the configuration
Look at the current state first
Get-MpPreference | Select-Object PUAProtection, EnableControlledFolderAccess, EnableNetworkProtection, AttackSurfaceReductionRules_Ids, AttackSurfaceReductionRules_Actions
Get-MpComputerStatus | Select-Object RealTimeProtectionEnabled, IsTamperProtected, AntivirusSignatureAge
On an untouched Windows 10/11 Home, according to Microsoft's documentation, the defaults are (sources for each item are in the footnotes):
PUAProtection : 2 ← audit mode: detects, does not block
EnableControlledFolderAccess : 0 ← off
EnableNetworkProtection : 0 ← off
AttackSurfaceReductionRules_Ids : ← not configured
AttackSurfaceReductionRules_Actions:
RealTimeProtectionEnabled : True
IsTamperProtected : True
AntivirusSignatureAge : 0
Real-time protection and tamper protection are on from the start. The four below are the ones that are not.
For what it is worth, here is the real output from my development machine — the one where I had dropped Norton and thought I had enabled three of these with PowerShell:
PUAProtection : 1
EnableControlledFolderAccess : 1
EnableNetworkProtection : 1
AttackSurfaceReductionRules_Ids :
AttackSurfaceReductionRules_Actions :
ASR was empty. Three were enabled; the fourth had never been touched. "I'm sure I did that" is not something you can verify without looking. That is half the reason this article exists.
1. Blocking PUA (potentially unwanted applications) — default is audit mode
Bundled installers, software that injects ads, and the kind of "N problems found!" tools that scare you into paying: this feature treats them as harmful even though they are not viruses.
Per Microsoft's documentation, on PCs not onboarded to Defender for Endpoint the default since definition 1.329.495.0 is audit mode (2) — detect and write an event log entry, but do nothing2.
# administrator PowerShell
Set-MpPreference -PUAProtection Enabled
Side effect: occasionally a legitimate tool is flagged as PUA. Check Windows Security → Protection history and add an exclusion if needed.
2. Controlled folder access — default is off
Stops programs you have not allowed from writing to protected folders such as Documents and Pictures — the last line of defence against ransomware. Off by default3.
Set-MpPreference -EnableControlledFolderAccess Enabled
Side effect: this is the one you will notice most. Right after enabling it, legitimate apps that save into Documents (editors, game saves, your own tools) may be blocked. When that happens, go to Windows Security → Virus & threat protection → Ransomware protection → "Allow an app through Controlled folder access". Running it in AuditMode for a few days first is a reasonable approach.
Set-MpPreference -EnableControlledFolderAccess AuditMode # log only
3. Network protection — default is off
Uses SmartScreen reputation data to block connections to malicious domains at the OS level, for every process, not just the browser. This is the layer commercial security suites sold as a "web shield". Off by default4.
Set-MpPreference -EnableNetworkProtection Enabled
A caveat, stated honestly: Microsoft's documentation describes this feature with Pro / Enterprise in mind. On Home the command above succeeds and Get-MpPreference returns 1 (measured), but I have not verified myself that connections are actually blocked on Home.
4. Attack surface reduction (ASR) rules — default is not configured
A set of behaviour-based rules such as "don't run executables that arrived by email" and "don't run executables that are rare and new". Microsoft's documentation states explicitly that ASR rules are "available on any edition of Windows that includes Microsoft Defender Antivirus (for example, Windows 11 Home)" and can be configured locally with PowerShell5. By default no rule is configured.
Start with the three rules that matter for download-borne threats, in audit mode first (going straight to Block can stop your own tools from running).
$rules = @(
'01443614-cd74-433a-b99e-2ecdc07bfc25', # block executables unless they meet a prevalence, age, or trusted-list criterion
'be9ba2d9-53ea-4cdc-84e5-9b1eeee46550', # block executable content from email and webmail
'd3e037e1-3eb8-44c8-a917-57927947596d' # block JavaScript / VBScript from launching downloaded executables
)
foreach ($r in $rules) { Add-MpPreference -AttackSurfaceReductionRules_Ids $r -AttackSurfaceReductionRules_Actions AuditMode }
Watch Event Viewer for a few days to two weeks (Microsoft-Windows-Windows Defender/Operational, event ID 1122 is the audit event). If none of your work tools trip the rules, raise them to Enabled (Block).
foreach ($r in $rules) { Add-MpPreference -AttackSurfaceReductionRules_Ids $r -AttackSurfaceReductionRules_Actions Enabled }
Undoing it
Set-MpPreference -PUAProtection AuditMode # back to default
Set-MpPreference -EnableControlledFolderAccess Disabled
Set-MpPreference -EnableNetworkProtection Disabled
foreach ($r in $rules) { Remove-MpPreference -AttackSurfaceReductionRules_Ids $r }
These commands work even with tamper protection on (tamper protection guards the core settings such as real-time protection, which can only be changed from the Windows Security UI).
They can quietly revert
This is the main point of the article. Windows Update, swapping security products, or your own actions can silently reset these to their defaults. Defender has no mechanism that tells you "a setting changed", so you will not notice. The minimum countermeasure is to run the Get-MpPreference command above periodically, or to have Task Scheduler dump the state to a log once a week.
# example: keep a weekly snapshot
Get-MpPreference | Select-Object PUAProtection, EnableControlledFolderAccess, EnableNetworkProtection, AttackSurfaceReductionRules_Ids |
ConvertTo-Json | Out-File "$env:LOCALAPPDATA\defender-posture-$(Get-Date -Format yyyyMMdd).json"
One paragraph of advertising
I am building a tray-resident tool that does the "check → enable → watch for drift" loop above, and it is in closed beta with testers wanted. It checks 19 items, including the four Defender settings, once an hour, reports only the ones that drifted, and enables things in two clicks ("show the plan → apply") after saving the previous values. It is not an antivirus and sends nothing anywhere. Beta testers get a one-year licence for free. If that sounds useful → Agent Fettle beta sign-up
Footnotes
-
AV-TEST: Test antivirus software for Windows 11 – Home User — June 2026, Microsoft Defender Antivirus (Consumer) 4.18: protection 6 / performance 5.5 / usability 6; Norton 360 26.4 & 26.5: 6 / 6 / 6. Both Top Product (checked 2026-09-17) ↩
-
Block potentially unwanted applications with Microsoft Defender Antivirus — table "Microsoft Defender Antivirus without devices onboarded to Defender for Endpoint" (1.329.495.0 and later: Audit mode (2)) ↩
-
Protect folders from ransomware with controlled folder access — "CFA is turned off by default." and "available on any edition of Windows that includes Microsoft Defender Antivirus (for example, Windows 11 Home)" (ms.date 2026-07-02) ↩
-
Use network protection to help prevent connections to malicious or suspicious sites — requirements list Windows 10/11 Pro or Enterprise ↩
-
Attack surface reduction rules reference — "ASR rules are a Microsoft Defender Antivirus feature that's available on any edition of Windows that includes Microsoft Defender Antivirus (for example, Windows 11 Home). You can configure ASR rules locally using PowerShell or Group Policy." ↩
